The AISec Study documents what AI security programs actually do, based on confidential interviews with the people running them.
UltraViolet Cyber sat down with security, AI, governance, and engineering leaders at 10 organizations across banking, enterprise software, healthcare, manufacturing, hospitality, government, and the nonprofit sector. Each organization was scored against a shared catalog of 64 activities across three domains: Direction & Oversight, Engineering & Usage, and Assurance & Protection. Every activity lands in one of three tiers: Established, Emerging, or Unobserved.
The result is a comparable, evidence-based view of AI security maturity across the data pool.
Data-pool averageRange across the 10 organizations (min and max)
What's in the report:
- Full capability and domain-level scores across all 10 organizations in the data pool
- The breadth-versus-depth gap, and what it means for where programs are actually exposed
- Findings on AI coding assistant governance and agent identity, the two areas with the widest gap between adoption and control
- A practitioner's view from Aravind Venkataraman, UltraViolet Cyber, on where the data points next
AI Governance by Design
UltraViolet Cyber Acquires Black Duck’s Application Security Testing Services Business
UltraViolet Cyber Launches Solstice